TUCoPS :: HP Unsorted V :: b06-4228.htm

Virtual War v1.5.0 SQL injection and XSS
Virtual War v1.5.0 SQL injection and XSS
Virtual War v1.5.0 SQL injection and XSS



Virtual War v1.5.0 SQL injection and XSS

http://[host]/vwar/war.php?s=[SQL]
http://[host]/vwar/war.php?page=[SQL]or[xss]
http://[host]/vwar/war.php?showgame=[SQL]
http://[host]/vwar/war.php?sortby=[sql]
http://[host]/vwar/war.php?sortorder=[sql]
http://host]/vwar/calendar.php?year=[xss]

vendor: www.vwar.de

google:"Powered by: Virtual War v1.5.0"

Discovered by Vampire

Connect Me : Vampire_chiristof@yahoo.com



TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH